High severity8.8NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2026-26794
CVE-2026-26794
Description
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:gl-inet:ar300m16_firmware:4.3.11:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 4.3.11
Patches
Vulnerability mechanics
References
1- github.com/sezangel/IOT-vul/tree/main/GL-iNet/GL-AR300M16/acl--add_groupnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.